← Home

Data Processing Agreement

Effective date: 1 August 2026

Mangroove FZ-LLC
License no. 47035430
FDBC5835
Compass Building
Al Shohada Road
Al Hamra Industrial Zone-FZ
Ras Al Khaimah
United Arab Emirates
info@creatorspa.io

This Data Processing Agreement (“DPA”) forms part of the CreatorsPA Terms of Use and applies where Mangroove FZ-LLC processes Personal Data on behalf of a Customer in connection with CreatorsPA.

This DPA is entered into between Mangroove FZ-LLC (“CreatorsPA”, “we”, “us”, “our” or the “Processor”) and the person or entity that has accepted the CreatorsPA Terms of Use and uses the Service as a controller or processor of Personal Data (“Customer”, “you” or “your”).

This DPA is incorporated automatically into the Terms of Use and does not require a separate signature. If CreatorsPA does not process Personal Data on your behalf, this DPA does not apply to that processing.

1. Purpose and Scope

This DPA governs the processing of Personal Data by CreatorsPA on behalf of the Customer when providing the CreatorsPA service. It is intended to satisfy applicable requirements for controller-processor arrangements under applicable Data Protection Laws, including the GDPR and UK GDPR where relevant.

CreatorsPA may also process certain information for its own purposes as an independent controller. That processing is outside the scope of this DPA and is governed by the CreatorsPA Privacy Policy. Examples include account administration, login information, security records, subscription management, billing references, legal compliance and similar operational information.

2. Definitions

For purposes of this DPA:

3. Roles of the Parties

For Personal Data processed under this DPA:

The Customer determines the purposes for which Customer Data is processed. CreatorsPA processes Customer Data only to provide, maintain, secure and support the Service in accordance with (1) the Terms of Use, (2) this DPA, (3) the Customer’s actions and instructions within CreatorsPA, and (4) other written instructions expressly accepted by CreatorsPA.

CreatorsPA acts as an independent Controller for information it processes for its own legitimate operational purposes, such as account administration, authentication, subscription management, security, fraud prevention, legal compliance and support administration.

4. Customer Instructions

The Customer instructs CreatorsPA to process Customer Data as reasonably necessary to provide the Service and perform the functionality selected by the Customer. Actions taken by the Customer through the Service, including connecting a channel, requesting AI generation, approving content, creating a calendar event or requesting another feature, constitute documented instructions for purposes of this DPA.

Any additional or special instruction outside the normal functionality of CreatorsPA will only become binding if CreatorsPA accepts it in writing. CreatorsPA will not process Customer Data for purposes unrelated to providing, operating, securing or supporting the Service unless required by applicable law, or the Customer has provided a separate lawful instruction.

If CreatorsPA reasonably believes that a Customer instruction violates Applicable Data Protection Law, we may suspend that instruction and inform the Customer unless we are legally prohibited from doing so.

5. Customer Responsibilities

The Customer is responsible for complying with its obligations under Applicable Data Protection Law. In particular, the Customer is responsible for:

Where Customer Data concerns a minor, the Customer is responsible for ensuring that the processing is lawful and that any required parental or guardian consent has been obtained. CreatorsPA does not independently collect age or date-of-birth information about minors appearing in Customer Content.

6. Special Categories of Personal Data

CreatorsPA is not designed for the intentional processing of special categories of Personal Data, including information concerning health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data or biometric data used for unique identification.

Customers should not intentionally submit such information unless the processing is lawful, necessary for the Customer’s use of the Service and permitted by CreatorsPA. Images, video, faces and voice recordings may be processed by CreatorsPA as ordinary content. CreatorsPA does not use facial images, voice recordings or similar information for biometric identification or authentication.

7. Nature and Purpose of Processing

CreatorsPA may process Customer Data to provide functionality requested by the Customer, including:

Customer Content is sent to an AI provider only when the Customer actively chooses to use a function requiring that AI processing. CreatorsPA does not routinely send Customer Content to AI providers in the background for unrelated purposes.

8. Categories of Personal Data

Depending on the features used by the Customer, Customer Data may include:

8.1 Content and conversation data

Conversations between the Customer and the CreatorsPA team are stored so that the Service can retain context and build on previous work. When a Customer sends a new message, only the recent conversation context reasonably required to process the request is sent to the relevant AI provider rather than the Customer’s complete conversation history. Image prompts and trend-analysis requests may be processed for the requested function without necessarily being retained as conversation history.

8.2 Connected social channel data

Depending on the platform and features used, CreatorsPA may process channel and profile information, channel identifiers, profile names, comments, publishing history, post information, YouTube video titles and descriptions, links to media hosted by third-party platforms, and OAuth access and refresh tokens.

CreatorsPA does not normally copy or permanently store social platform media files solely because a social account is connected. Media may remain hosted by the relevant platform, while CreatorsPA stores references or links where required for the Service.

8.3 Analytics information

For posts published through CreatorsPA, performance information such as views, likes, comment counts and, on Facebook, shares may be retrieved from the connected platform and cached with the relevant post.

These metrics are refreshed at most every 30 minutes. CreatorsPA does not maintain a historical time series of those metrics.

CreatorsPA does not currently retrieve reach, watch time, subscriber or follower counts, or audience demographics through this functionality.

8.4 Generated media

Everything generated for the Customer — images, video and voice — is downloaded into CreatorsPA’s EU-based storage as soon as it is produced. CreatorsPA does not store links pointing at an AI provider’s servers, so Customer Content does not depend on a provider link remaining available. Files are held in private storage and served through short-lived signed links. The assistant’s read-aloud audio is streamed to the browser and never stored.

8.5 Support information

Where the Customer contacts support, Customer Data may include information voluntarily supplied for troubleshooting, such as screenshots, error messages, content examples, channel identifiers or other information needed to investigate the issue.

9. Categories of Data Subjects

Customer Data may relate to the Customer; people appearing in Customer Content; individuals whose voices or likenesses appear in content; people commenting on or interacting with connected channels; collaborators; customers or clients of the Customer; people the Customer chooses to reference in content; and minors appearing in lawfully submitted Customer Content.

CreatorsPA does not independently establish a relationship with those third-party Data Subjects merely because their Personal Data is included in Customer Data.

10. Data We Process as Controller

Certain information is processed by Mangroove FZ-LLC for its own purposes and is not Customer Data processed under this DPA. This may include:

This processing is governed by the CreatorsPA Privacy Policy. Signing in with Google requests identity only — name and email address. Permission to reply to YouTube comments is requested separately when a channel is connected, and permission to create calendar events is requested separately at the first reminder request. Gmail and Google Drive are never requested. Adding a further YouTube channel later requests YouTube permission only.

11. Payments

CreatorsPA does not receive or store payment card numbers, bank account details or payment credentials. Payments are handled by Paddle as merchant of record under Paddle’s applicable terms.

CreatorsPA may store limited non-sensitive identifiers received from Paddle, such as customer identifier, subscription identifier, plan, subscription status and renewal date. These are used to provide the correct subscription access and administer the Customer’s account and are processed by CreatorsPA as Controller rather than under the Processor activities governed by this DPA.

12. Google Calendar

CreatorsPA currently supports Google Calendar where the functionality is available. CreatorsPA does not read or import the Customer’s existing calendar. Calendar information is processed only when the Customer directly instructs CreatorsPA to create an event. The information required for that event is sent to Google and is not retained by CreatorsPA as a stored copy after the event has been created.

13. AI Processing

CreatorsPA uses third-party AI providers to perform specific functions requested by the Customer. Depending on the feature, these may include providers for text generation, image generation, video generation, voice generation and trend analysis.

Customer Data is sent to an AI provider only where required for the specific function activated by the Customer. AI providers engaged as subprocessors are required to process Customer Data under contractual safeguards and not for their own independent purposes. CreatorsPA does not permit Customer Content processed through these integrations to be used to train the providers’ general AI models.

Some AI providers may retain inputs temporarily, typically for up to 30 days, for legitimate security, abuse monitoring or service-protection purposes before deletion, subject to their contractual terms.

14. No Training on Customer Content

CreatorsPA does not use Customer Content to train or improve CreatorsPA’s own general AI models. CreatorsPA does not authorise its AI subprocessors to use Customer Content for training their general models.

This does not prevent CreatorsPA from using anonymised and aggregated operational information that does not contain identifiable Customer Content to improve the security, reliability or operation of the Service.

15. Subprocessors

The Customer grants CreatorsPA general written authorisation to engage subprocessors where reasonably necessary to provide the Service.

The current list of subprocessors is maintained separately on the CreatorsPA Subprocessors page.

The list may include providers supporting database and file storage, application hosting, transactional email, authentication, AI processing, public social media data retrieval, support email infrastructure, and other infrastructure necessary to provide the Service.

One of those providers is SocialCrawl, used for public social media data retrieval. When the Customer researches a channel or topic, CreatorsPA sends a query — such as a channel name or keyword — together with the chosen platform and time range, and receives publicly available platform data in return. No account data or Customer Content is sent. Trend results are aggregated without the author’s identity; creator search and networking results keep public profile details so that a relevant comment can be drafted, and networking records are deleted automatically after 14 days. Processing may occur outside the EU/EEA under applicable transfer safeguards.

CreatorsPA requires each subprocessor that processes Customer Data to be subject to contractual obligations providing an appropriate level of data protection for the processing performed. CreatorsPA remains responsible for its subprocessors to the extent required by Applicable Data Protection Law.

16. Changes to Subprocessors

CreatorsPA may add, replace or remove subprocessors. Where required by Applicable Data Protection Law, CreatorsPA will provide at least 30 days’ advance notice of a new or replacement subprocessor. Notice may be sent to the email address associated with the Customer’s CreatorsPA account and may direct the Customer to the updated Subprocessors page.

The Customer may object during that period where it has reasonable and documented grounds relating specifically to data protection. The parties will attempt in good faith to resolve a valid objection. Where no reasonable solution is available, CreatorsPA may modify the affected processing, offer a commercially reasonable alternative where available, discontinue the affected feature, or permit termination of the affected Service where required by Applicable Data Protection Law.

An objection based solely on commercial preference or a general dislike of a supplier does not constitute a valid data-protection objection.

17. Confidentiality

CreatorsPA ensures that persons authorised to process Customer Data are subject to appropriate confidentiality obligations. Access to production data is restricted to authorised personnel and is permitted only where reasonably necessary, including for troubleshooting, investigating a technical fault, investigating a Security Incident, investigating misuse or a complaint, complying with a lawful request, or maintaining the integrity of the Service. Access is granted on a need-to-know basis.

18. Security Measures

CreatorsPA maintains technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Current measures include:

CreatorsPA does not use third-party advertising or analytics tracking cookies for the operation described in this DPA. Security measures may evolve as the Service changes, provided that CreatorsPA does not materially reduce the overall level of protection required by Applicable Data Protection Law. CreatorsPA does not currently claim SOC 2, ISO 27001 or similar certification.

19. Security Incidents

CreatorsPA maintains procedures for responding to suspected or confirmed Security Incidents. Where a Security Incident involving Customer Data is confirmed, CreatorsPA will take reasonable steps to investigate the incident, contain and mitigate its effects, preserve relevant evidence, document the incident, take reasonable measures to prevent recurrence, and notify the affected Customer without undue delay where required by Applicable Data Protection Law.

The notification will include information reasonably available to CreatorsPA that may assist the Customer in meeting its own legal notification obligations. Information may be provided in stages where it is not reasonably possible to provide all relevant information at the same time. Notification of a Security Incident does not constitute an admission of fault or liability by CreatorsPA.

20. Data Subject Requests

If CreatorsPA receives a request directly from a Data Subject concerning Customer Data processed under this DPA, CreatorsPA will not independently respond to the substance of the request unless instructed by the Customer or required to do so by applicable law. Where reasonably possible, CreatorsPA will direct the Data Subject to the Customer.

Taking into account the nature of the processing, CreatorsPA will provide reasonable assistance to the Customer with requests concerning access, correction, deletion, restriction, portability, objection and other applicable Data Subject rights. Such additional assistance may be provided at the Customer’s expense where it requires work outside the normal functionality of the Service.

21. Regulatory Assistance and DPIAs

Taking into account the nature of the processing and information reasonably available to CreatorsPA, we will provide reasonable assistance with Data Protection Impact Assessments, consultations with supervisory authorities, regulatory inquiries relating to Customer Data, and demonstrating compliance with applicable controller obligations. Additional assistance outside the normal operation of the Service may be charged to the Customer at CreatorsPA’s reasonable cost.

22. Audits and Compliance Information

CreatorsPA will make information reasonably necessary to demonstrate compliance with this DPA available to the Customer. No more than once in any 12-month period, unless required by Applicable Data Protection Law or following a material Security Incident, the Customer may request reasonable security or compliance information relevant to the processing.

CreatorsPA may satisfy such a request by providing available security documentation, policies, questionnaires, audit summaries, third-party reports or equivalent compliance information.

An on-site or intrusive audit may only be requested where required by Applicable Data Protection Law or applicable SCCs, and the information reasonably available from CreatorsPA is insufficient. Any audit must be conducted on reasonable advance written notice, occur during normal business operations, avoid unreasonable disruption, protect other customers’ confidential information, not require disclosure of source code, credentials or information that could compromise security, and be at the Customer’s expense unless required otherwise by mandatory law.

23. Data Location

CreatorsPA’s primary database and file storage for account data and Customer Content is hosted in the European Union. CreatorsPA currently uses EU-based database and storage infrastructure in Frankfurt, Germany.

Transactional email is delivered through Resend. Email delivery may use Resend’s Ireland region, while certain Resend account data, email metadata, logs and API records may be stored in the United States.

Support email received through info@creatorspa.io is handled through Google Workspace.

The application is hosted through Vercel, which may process technical information required to deliver and secure the Service.

Certain processing may also involve access to or processing of Customer Data outside the EU/EEA, including AI processing by approved providers, authorised access to production systems from the United Arab Emirates, and other processing disclosed on the Subprocessors page.

CreatorsPA uses appropriate transfer safeguards where required by Applicable Data Protection Law.

24. International Data Transfers

Where Customer Data subject to the GDPR is transferred to a country that does not benefit from an applicable adequacy decision or other valid transfer mechanism, CreatorsPA will use an appropriate safeguard as required by Applicable Data Protection Law. Where necessary, the European Commission Standard Contractual Clauses adopted under Decision (EU) 2021/914 are incorporated into this DPA by reference.

24.1 EU SCC module

Where the Customer is a Controller and CreatorsPA is the Processor, Module Two — Controller to Processor applies. Where the Customer is itself a Processor and CreatorsPA acts as a Subprocessor, Module Three — Processor to Processor applies to the extent necessary.

For purposes of the SCCs: the Customer is the data exporter; Mangroove FZ-LLC is the data importer; the information contained in this DPA and its schedules completes the relevant Annexes to the SCCs where applicable; the supervisory authority will be determined in accordance with the SCCs and Applicable Data Protection Law; the governing law for the SCCs will be the law of Ireland, where a choice is required and legally permitted; and the courts of Ireland will have jurisdiction for disputes arising specifically under the SCCs where required by the SCCs.

The SCCs prevail over this DPA to the extent of a direct conflict concerning an international transfer governed by those SCCs.

25. UK International Transfers

Where Customer Data subject to UK GDPR is transferred in a manner requiring an appropriate safeguard, the then-current UK International Data Transfer Addendum to the European Commission SCCs will apply to the extent required by UK Data Protection Law.

For those transfers: the applicable EU SCCs are incorporated as described above; the UK Addendum is incorporated by reference; the information in this DPA and its schedules may be used to complete the applicable tables of the UK Addendum; and mandatory UK law and jurisdiction provisions contained in the UK Addendum will apply to the relevant transfer. The UK Addendum prevails over inconsistent terms of this DPA only to the extent required for the applicable UK restricted transfer.

26. Onward Transfers

Where CreatorsPA permits a subprocessor outside the EU/EEA or UK to process Customer Data, CreatorsPA will require an appropriate contractual and legal transfer mechanism where required. This may include the SCCs, the UK Addendum, an applicable adequacy mechanism, or another lawful transfer safeguard permitted by Applicable Data Protection Law. CreatorsPA will assess and implement additional safeguards where required by applicable transfer law.

27. Connected Social Accounts

CreatorsPA may store access and refresh tokens required to maintain connections to social platforms. These tokens are used only to provide functionality authorised by the Customer.

When a Customer disconnects a social channel, CreatorsPA’s access to the channel stops; the relevant access credentials are revoked or invalidated where technically available; and CreatorsPA stops retrieving new information from that connection.

Disconnecting a channel inside CreatorsPA also deletes the data stored for that channel in the same action — comments, drafts, learned reply examples and channel records. It is not retained for later manual clean-up. If the Customer instead revokes access at the platform without disconnecting inside CreatorsPA, our access stops but the previously stored data is not yet removed automatically; it can be removed by disconnecting the channel or deleting the account.

28. YouTube Data

YouTube data is subject to additional requirements imposed by Google and YouTube. Where the Customer disconnects a YouTube channel inside CreatorsPA, the associated YouTube API data is deleted immediately as part of that action. Where authorisation is instead revoked at Google, expires or can no longer be verified, CreatorsPA does not currently detect that automatically; the data is deleted when the Customer disconnects the channel or deletes the account, and on request within the period required by applicable YouTube policies.

This requirement may apply even where historical data from other connected platforms remains in the Customer’s account. The Customer may also revoke CreatorsPA’s access through the Customer’s Google Account security settings.

29. Data Retention During Active Use

Customer Data is generally retained for as long as required to provide the features selected by the Customer. For example:

CreatorsPA may retain limited operational or compliance records for longer where required by law or reasonably necessary to establish that an action, consent or deletion occurred. Where possible, such records may be anonymised.

30. Account Deletion

Account deletion in CreatorsPA is immediate and irreversible. There is no deactivation state and no recovery period.

The Customer confirms deletion by typing a confirmation word, after which third-party access is revoked where technically possible, stored files are deleted, any voice copies are permanently deleted at the applicable voice provider, and the account is deleted together with the data in every connected table.

CreatorsPA cannot restore an account after deletion.

Two limited types of records are deliberately retained: usage records required for accounting, with the account identifier removed, and records showing that voice consent was given and that voice deletion was carried out. Those records may contain an account identifier but do not contain Customer Content.

31. Backup Retention

When Customer Data is permanently deleted from active systems, deleted files such as stored images and voice files are removed from active storage; deleted database information may remain temporarily in encrypted backups for up to seven days; and those backups are then overwritten through the normal backup cycle.

Backup copies are isolated from ordinary production use and are used only for legitimate backup or disaster-recovery purposes. If a backup must be restored, CreatorsPA will take reasonable steps to ensure that data previously scheduled for permanent deletion is not returned to ordinary use.

32. Individual Deletion Requests

Customers may use the deletion functionality provided within CreatorsPA to remove data supported by those features. In exceptional circumstances, a Customer may contact info@creatorspa.io to request accelerated or additional deletion.

CreatorsPA will consider such requests reasonably but does not guarantee that a special deletion request can be completed outside the normal functionality or retention processes unless required by Applicable Data Protection Law.

33. Return and Export of Data

While an account is active, Customers may use available export functionality to obtain Customer Data supported by the Service.

Because account deletion is immediate and irreversible, there is no post-deletion recovery or export period.

Once account deletion has been confirmed, CreatorsPA cannot restore the account or provide an ordinary export of data that has been permanently deleted from active systems.

Limited records and encrypted backup data may remain only as described in Sections 30 and 31 of this DPA.

34. Operational and Security Logs

CreatorsPA retains operational and security information only for as long as reasonably necessary for security, troubleshooting, abuse prevention, compliance, dispute resolution, accounting or legal obligations.

CreatorsPA does not build advertising or analytics profiles from technical activity. CreatorsPA records the Customer’s last sign-in date for account and inactivity management. CreatorsPA does not maintain its own tracking profile containing IP address, device or browser history for advertising or analytics. Infrastructure providers such as hosting or database providers may process IP addresses and similar technical information as necessary to deliver and secure their services.

35. Automated Decision-Making

CreatorsPA does not use Customer Data to make solely automated decisions about an individual that produce legal effects or similarly significant effects within the meaning of applicable Data Protection Law. Automated security or abuse-detection systems may flag activity for review or technical intervention, but this does not change the Customer’s rights under applicable law.

36. Government and Legal Requests

If CreatorsPA receives a legally binding request from a public authority concerning Customer Data, CreatorsPA will handle the request in accordance with applicable law. Where legally permitted and reasonably possible, CreatorsPA may inform the affected Customer before disclosing Customer Data.

CreatorsPA will not voluntarily provide Customer Data to a public authority except where required by law, necessary to protect rights or safety in an emergency, or otherwise permitted under Applicable Data Protection Law. Where the SCCs apply, CreatorsPA will comply with the government-access obligations contained in those SCCs.

37. Term and Termination

This DPA begins when the Customer accepts the CreatorsPA Terms of Use and applies for as long as CreatorsPA processes Customer Data on behalf of the Customer. The DPA does not require a separate signature.

Where CreatorsPA materially breaches this DPA, the Customer must first provide CreatorsPA with a reasonable opportunity to remedy the breach where the breach is capable of remedy. Termination rights apply where required by Applicable Data Protection Law, required by the applicable SCCs or UK Addendum, a material breach cannot reasonably be remedied, or a material breach remains unremedied after a reasonable opportunity to correct it.

Termination does not remove obligations concerning confidentiality, deletion, liability, international transfer protections or other provisions that by their nature survive termination.

38. Liability

The liability provisions and limitations contained in the CreatorsPA Terms of Use apply to this DPA.

For Customers using the Service for business or professional purposes, to the maximum extent permitted by applicable law, Mangroove FZ-LLC’s aggregate contractual liability arising out of or relating to this DPA will not exceed USD 100.

Nothing in this DPA limits or excludes liability where such limitation or exclusion is prohibited by Applicable Data Protection Law, the SCCs, the UK Addendum or another mandatory legal requirement.

Where the Customer is a consumer, nothing in this Section limits any mandatory consumer rights.

The SCCs or UK Addendum prevail to the extent their mandatory liability provisions conflict with this Section.

39. Costs of Assistance

Normal compliance with CreatorsPA’s obligations as Processor is included as part of the Service. Where the Customer requests significant assistance beyond the standard functionality or ordinary legal obligations of CreatorsPA, including bespoke audits, extensive Data Subject request assistance, regulatory support or custom technical work, CreatorsPA may charge reasonable costs for that assistance. CreatorsPA will inform the Customer before incurring material additional charges where reasonably practical.

40. Order of Precedence

If there is a conflict between documents governing the processing of Customer Data, the following order applies: (1) mandatory provisions of Applicable Data Protection Law; (2) applicable SCCs or UK Addendum; (3) this DPA; (4) the CreatorsPA Terms of Use. This order applies only to the extent of the relevant conflict.

41. Governing Law

Except for international transfer provisions that require a different governing law, this DPA is governed by the laws of the United Arab Emirates. Subject to mandatory rights and the transfer provisions above, disputes concerning this DPA are subject to the courts of Ras Al Khaimah, United Arab Emirates.

Where the EU SCCs apply, their mandatory governing-law and jurisdiction provisions apply to matters governed by those clauses. Where the UK Addendum applies, its mandatory governing-law and jurisdiction provisions apply to the relevant UK transfer.

42. Changes to this DPA

CreatorsPA may update this DPA where reasonably necessary to reflect changes in the Service, reflect changes in subprocessors, comply with changes in law, implement new regulatory guidance, improve privacy or security protections, or clarify existing obligations. Material changes will be communicated in accordance with the Terms of Use and Applicable Data Protection Law. No amendment may reduce protections required by mandatory Applicable Data Protection Law.

43. Contact

Questions about this DPA, data protection or Security Incidents may be sent to info@creatorspa.io.

Mangroove FZ-LLC currently manages privacy matters internally and has not appointed a formal Data Protection Officer.

Schedule 1 — Details of Processing

A. Subject Matter

Processing of Personal Data reasonably necessary for CreatorsPA to provide content-creation, AI, social-channel, publishing, support, calendar and related functionality selected by the Customer.

B. Duration

For the duration of the Customer’s use of the Service and, following termination or account deletion, only for the limited retention, backup or legal-compliance periods described in this DPA.

There is no account recovery period following deletion.

C. Nature of Processing

Collection; access; transmission; storage; organisation; retrieval; consultation; generation; adaptation; display; analysis; publication at the Customer’s instruction; deletion; restriction; backup; and other processing necessary to provide the Service.

D. Purposes

Providing requested CreatorsPA features; storing Customer Content; maintaining conversational context; AI generation requested by the Customer; trend research; managing connected social accounts; retrieving comments and platform information; scheduling and publishing Customer-approved content; creating Google Calendar events at the Customer’s request; providing technical support; maintaining security; preventing abuse; troubleshooting; backup and disaster recovery; and complying with lawful instructions.

E. Types of Personal Data

Names; usernames; social profile information; social channel identifiers; comments; textual content; images; photographs; voice recordings; video; likenesses; conversation content; prompts; AI-generated content; YouTube titles and descriptions; publishing history; OAuth tokens; links to platform-hosted media; calendar-event information processed transiently; support information; and other Personal Data voluntarily supplied by the Customer through the Service.

F. Categories of Data Subjects

The Customer; people appearing in Customer Content; commenters and social-channel users; collaborators; customers or clients of the Customer; other persons referenced in Customer Content; and minors lawfully appearing in Customer Content.

G. Special Category Data

CreatorsPA is not intended for the intentional processing of special category Personal Data. Biometric identification is not performed.

Schedule 2 — Technical and Organisational Measures

CreatorsPA currently maintains measures including:

Encryption

Access Control

Application Security

Data Minimisation

Storage and Backup

Personnel Security

Incident Management

CreatorsPA maintains procedures intended to identify suspected incidents; investigate and contain incidents; document confirmed incidents; mitigate adverse effects; preserve relevant evidence; implement corrective measures; and notify affected Customers without undue delay where required.

Service Providers

Subprocessors are required to be subject to appropriate data protection obligations and international transfer safeguards where required.

Schedule 3 — International Transfer Information

Data Exporter

The Customer identified through the CreatorsPA account and Terms of Use. Role: Controller, in the ordinary case; or Processor where the Customer processes Personal Data on behalf of another Controller.

Data Importer

Mangroove FZ-LLC, Licence No. 47035430, Ras Al Khaimah, United Arab Emirates. Role: Processor / Subprocessor. Contact: info@creatorspa.io

Transfer Frequency

Continuous or intermittent for the duration of the Service, depending on the features used by the Customer.

Transfer Purpose

To provide the functionality described in this DPA.

EU SCC Module

Module Two where Customer is Controller and CreatorsPA is Processor. Module Three where Customer is Processor and CreatorsPA is Subprocessor.

EU SCC Governing Law and Courts

Ireland, where a choice is required under the SCCs.

Technical and Organisational Measures

The measures described in Schedule 2 apply.

Subprocessors

The current list is maintained on the CreatorsPA Subprocessors page.

UK Transfers

Where required, the UK International Data Transfer Addendum applies together with the relevant EU SCC module.